LWN.net Logo

Ubuntu alert USN-505-1 (vim)

From:  Kees Cook <kees@ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-505-1] vim vulnerability
Date:  Tue, 28 Aug 2007 14:53:01 -0700
Message-ID:  <20070828215301.GD5788@outflux.net>
Cc:  bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk

=========================================================== Ubuntu Security Notice USN-505-1 August 28, 2007 vim vulnerability CVE-2007-2953 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: vim 1:6.4-006+2ubuntu6.1 Ubuntu 6.10: vim 1:7.0-035+1ubuntu5.2 Ubuntu 7.04: vim 1:7.0-164+1ubuntu7.2 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Ulf Harnhammar discovered that vim does not properly sanitise the "helptags_one()" function when running the "helptags" command. By tricking a user into running a crafted help file, a remote attacker could execute arbitrary code with the user's privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 182627 4e1ffc35c25e3abff107ae6a602e7f71 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 1323 bc62b8688b56a38e6ba0fc60f50f0174 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 5740778 b893e7167089e788091f80c72476f0d3 Architecture independent packages: http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-doc... Size/MD5: 1732746 5130bb2b37e7304802a30b8e63f55215 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-run... Size/MD5: 3593324 75e90cc1e16416307351657fffc51ca9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 83386 4a1df06635c09754d20bf461d48e4ea1 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 843742 e4ac0160da31facc449e9cb211d31f7d http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gui... Size/MD5: 69872 c2781a9b6a3c7475f16d4f6a683ccf45 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 443526 01fafda91a9ddb14aa48526d130d5c76 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 663192 3d3514d98383621b47558204e6e8db63 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 841750 189964e0193fadecd1a436c9e110e7e1 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 845916 1384981fba0f4404998f7cb3b1c851ed http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 841762 684748a866da88c515a61de2706d599e http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 836814 112e41f2715faa1034f326a3acbb9482 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 799452 7ea073b73e4f643ee4797cdf04ca416f i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 82946 cfdb0bff7d5ca60082f2fdfff7afecce http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 712656 41b0d03994e30dde0dc101aff0a4ed9b http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gui... Size/MD5: 69868 e83d8d4daf4ec64ac87d6954131e15b7 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 365224 ba5e4b0eba3497162d0a37dc6c65a315 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 554138 e073432b5c7fc9ec78506e864706a6e8 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 710742 827cdd37339c305f37cb451e30d56ec8 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 717206 9ffa5ed3722acd29920269385e597ac5 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 710762 fa4c5b5470228c502738cfd173d217e7 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 706550 8b5c48733615cac4c5488a058181ac4f http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 670476 4cbcb52adedff92b9f855f5e25b27ceb powerpc architecture (Apple Macintosh G3/G4/G5): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 83384 c11572d56bb5d1d7c860b4bbd9355931 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 803234 85be382df9a4e67f11ecc806f9a731e2 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gui... Size/MD5: 69890 96c43a164ffcc4cc74b0598d7428fddd http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 418678 9b1eefe8e58146657928305ec7e40c62 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 630358 8151eaf4b5230716f8acf41c374688d0 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 800714 a99a582480fe5ee271be0bd59de86e72 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 807998 2af88e3a3fd5f6b8e78eedfd8d4808b2 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 800728 b7de422c49ef1739743d0bef52e0b5a0 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 795132 7ded4b5da4fa05ed92178bb6d716417c http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 759284 73b45bae0483b7f984062028ccd64bb5 sparc architecture (Sun SPARC/UltraSPARC): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 83172 95e21e4e57a54dac3a506d103e5c667d http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 750584 ffa44c76fb8dd2889dbc4c99468fd979 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gui... Size/MD5: 69880 93ad91ac71663d62b1962b2eb1f74261 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 385058 790641ef04d07b8d0305f788a134ec08 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_6.4... Size/MD5: 583960 d687e3985caba7206c56918711d85320 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 747912 a98b0e3db5bcd39531b63fbb92a57690 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 755336 5be6682474b4aa3fa61792ec082a9f2d http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 747934 0ff707bd925946e6a7ca0f7778b2f23d http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 743828 3121568af4d162b51b4bb1feaf7e70a9 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 707522 e252a4171a4968be7df057fee671b9b8 Updated packages for Ubuntu 6.10: Source archives: http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 181857 b7e8feb2ae1fafb9761f2cf6f325e5a3 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 1368 b0d9718db2940340ad612121f84b844d http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 8457888 9ba05680b0719462f653e82720599f32 Architecture independent packages: http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-doc... Size/MD5: 2033296 06d60c25e12f2c38400788dc6b05cf1e http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gui... Size/MD5: 88328 82059ed083f291af4b5b31daf2518bbf http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-run... Size/MD5: 6336890 e15cfb0d32463a4d8bf6dd1dd98f3d4a amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 192782 795614d3ee6c3d7b6e93eda599f65db3 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 1031706 bbaaf8159af12dfb8c397b5a28c930bb http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 617368 4337da01937f4e65db59c1e3f96c5da3 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 838540 f71facb2321d6f0924fb2d1ea82b0d0a http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1059336 bd1a3d386a0aee8616dbc09d676218c1 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1029644 b14c5d4ecc86ed17c82452d8d5e62566 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1033072 be6a6b2fb6440a79ea8cedd6899eec1a http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1029660 c520480ab5ae41fdddfd55f0bda68f7f http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1024802 e1e1ff7ece3b196e49b3e9256e3f48b6 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 982178 2540b0ebda6e7228d546fb2a51026035 i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 192502 e97435e4d2b561e048d4153a28fbac72 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 909546 492838887d9816c1120aa587757b1df0 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 534524 f764eb7ba9b422cfc07ea3fb284e1b27 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 735658 c7414d902164a823583fb7bf4e6f0f25 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 935756 866c061d7a6142f14dfc973359f3d07b http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 906790 04591936cd4c7d214f335483f35e8510 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 913152 dbc6037b5b8eb838430b83542fe0d62b http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 906798 3028693cb063afc90bd53473aed290a8 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 901722 7b9ea3e0479ff3ec7414e86ec768eb83 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 862240 4b60403d169a7cbe6d6bec86933be671 powerpc architecture (Apple Macintosh G3/G4/G5): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 192834 989305e5642347c0097ac0cb2326561a http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 996268 302d54c27f36a885066fc83686623619 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 594854 9ba0bc9f67fab978d7a87c1585b440d6 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 812518 39a1ec4ad440341c0acb2079fb6f99a0 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1024596 b67bb1ec6be7e0948e3b68e28cbb3a91 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 993952 3419d3942725cff749d64d9471ae53f6 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 999524 43c43c46d207600aede04ed03b299c0b http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 993958 e1ea89147d57c85deb4bb05fd1a8ac90 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 989278 e19d43f8f218efb9be96b152af931807 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 947818 35a919506b5ddaf91113e32381961185 sparc architecture (Sun SPARC/UltraSPARC): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 192662 2adfdcd28d316184f06a1bacddeae068 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 934006 cca96a544aa3cea50a8ce5189342c863 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 546580 50b7cd42096f737469eefba290e5cba0 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 755586 3eef053e29d509a4ffb11bc2bbfa1c62 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 960394 c6fd96a4af831e492258a11f86d4a3d8 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 931872 2dafbefdb820d2d7320b5546f647f7d0 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 937496 0fa0cc6787f4b12621845f71969a635b http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 931886 65a7ff1be27e4a0f67c4dc57ae6b8546 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 927334 b50e18043cef39de22544c769f2bbb92 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 884948 9a2290c6307788a4731b89886021c6ec Updated packages for Ubuntu 7.04: Source archives: http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 327982 ede2edc4e701870136aa1a9a87c7482b http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 1513 2784f664344454758f13a8768523758d http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 8457888 9ba05680b0719462f653e82720599f32 Architecture independent packages: http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-doc... Size/MD5: 2038892 18a75c717a878f2998afa22244db63b2 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gui... Size/MD5: 146382 e62fb12f9f1888511a5d3b5a11e7e4d3 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-run... Size/MD5: 5210012 f7d4aaffc9ddc7d7cf78f5bec4f8deaa amd64 architecture (Athlon64, Opteron, EM64T Xeon): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 186484 33395b4e222b58783d739c93e4512494 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 1053612 53ee9314c6398f0252a3d51879d6cdb9 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 620008 a4a2d1bb31dfb84af4db433b33e397c6 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 842860 cd63b03474ec799bc2d8fb4e98c1a9b2 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1081306 549b2f3abb9f1c43b1b6f83342176199 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1051648 85440df8ee45004bddee4307dbfe56f0 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1054890 f3c9cdaf4455983a7992464e245d6e0f http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1051660 871dc4375df4183a8ddc1b4600c187b9 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1046498 d099bc7703c25afb45b405b828231e06 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 986246 bd1fdb9330169446fa373184e8ea34fd i386 architecture (x86 compatible Intel/AMD): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 186152 3a6e96c92eb2f492c1ddc9816a1c5bd4 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 929942 ec4130a02739c31c0d74cfe15c913686 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 536600 65bb2db95e21c78161f33ed5beb93f00 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 738414 4a399d34f59012bced37069a1eda6f3a http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 956894 4854e10927899294862eb42bb4bbc0b7 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 927342 00f4ee47f6fd3e34e4bedcc57e7cbe4e http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 933718 bd2ffd9ee3f12d109ed85dca22adad15 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 927350 7d688c2e782734e7c8b1357b565d744e http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 922626 f732ef52ec682684f08e330df89a20ec http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 864832 3d9b0a276f16cc6b8a3c6e3858bc0127 powerpc architecture (Apple Macintosh G3/G4/G5): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 186786 3eae5ff347880905e600abcee7e80592 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 1027660 011212e1ce29dde2bc824411a556994a http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 599414 8558d3ee15129facf3f2c33eba2dbd8c http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 818338 13b45b9a9b1a2f95c98a4c1eee234848 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1057638 f9d7914bef6a78c4bd02de395d471bf4 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1024602 e1ac906f18dd74cb05008910fc533d5d http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1032278 720ef6dd839c36d7af917ab99e23e8ed http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1024618 ef8d65973058db3b1cb0f75b4874f3b6 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 1020410 7c3e93ffb4d1f86e9d75e344f7465f57 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 960908 682516782a5a9128220e762c6cb494de sparc architecture (Sun SPARC/UltraSPARC): http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-com... Size/MD5: 186374 c122463c6439c04616e26c1457f84176 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-gno... Size/MD5: 959196 be60b1fe8ed2b6a28740fcab6d0cb4b6 http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim-tin... Size/MD5: 549260 a2230f3e5e30e08f41f8cf41da8b887b http://security.ubuntu.com/ubuntu/pool/main/v/vim/vim_7.0... Size/MD5: 759070 468b139be22bb8632b25ab3e44ed4218 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 986346 e677905db75c3a5636813d785b57032f http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 957552 75e50ade1e8f47e7a692ca0493932be9 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 963342 37158dcc06887d48a5dfb553fbb38365 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 957566 54d5758f4663fa6b4607c828ed8d71f2 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 952760 76124a4d49d4f976f6fdc445be3cb8a3 http://security.ubuntu.com/ubuntu/pool/universe/v/vim/vim... Size/MD5: 892642 3f32f53a74546b1ed76ea2a7d7bd37aa


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds